2.6
    Low

    CVE-2003-1135

    Last Modified: 11 Dec 2012

    Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

    Source:Hat-Squad Security Team
    Published:31 Dec 2003
    2.1
    Low

    CVE-2003-1134

    Last Modified: 11 Dec 2012

    Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

    Source:Marc Schoenefeld
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1131

    Last Modified: 18 Dec 2012

    PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

    Source:Zero X
    Published:31 Dec 2003
    2.6
    Low

    CVE-2003-1129

    Last Modified: 10 Nov 2012

    Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

    Source:cesaro
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1123

    Last Modified: 15 Nov 2012

    Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.

    Source:Marc Schoenefeld
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1118

    Last Modified: 4 Oct 2017

    Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.

    Source:zillion
    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1097

    Last Modified: 8 Nov 2012

    Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

    Source:Davide Del Vecchio
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1096

    Last Modified: 18 Dec 2012

    The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.

    Source:Cisco Security
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1092

    Last Modified: 28 Oct 2012

    Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.

    Source:CrZ
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1091

    Last Modified: 11 Nov 2012

    Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.

    Source:Sir Mordred
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1090

    Last Modified: 25 Oct 2012

    Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.

    Source:Knud Erik Hojgaard
    Published:6 Feb 2003
    5
    Medium

    CVE-2003-1089

    Last Modified: 30 Nov 2012

    index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.

    Source:Zone-h Security Team
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1088

    Last Modified: 29 Nov 2012

    Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.

    Source:G00db0y
    Published:11 Aug 2003
    7.5
    High

    CVE-2003-1086

    Last Modified: 17 Nov 2012

    PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.

    Source:frog
    Published:17 Jun 2003
    5
    Medium

    CVE-2003-1085

    Last Modified: 1 May 2013

    The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.

    Source:MurDoK
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1083

    Last Modified: 14 Dec 2012

    Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.

    Source:Shadowinteger
    Published:31 Dec 2003
    1.2
    Low

    CVE-2003-1073

    Last Modified: 24 Oct 2012

    A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.

    Source:Wojciech Purczynski
    Published:31 Dec 2003
    2.1
    Low

    CVE-2003-1071

    Last Modified: 20 Oct 2012

    rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.

    Source:Brant Roman
    Published:3 Jan 2003
    7.2
    High

    CVE-2003-1055

    Last Modified: 4 Oct 2017

    Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.

    Source:Andi
    Published:3 Jul 2003
    5
    Medium

    CVE-2003-1054

    Last Modified: 5 Nov 2012

    mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.

    Source:zillion
    Published:16 Apr 2003
    7.2
    High

    CVE-2003-1052

    Last Modified: 29 Nov 2012

    IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.

    Published:20 Aug 2004
    7.2
    High

    CVE-2003-1051

    Last Modified: 7 Nov 2017

    Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

    Source:SNOSoft
    Published:20 Aug 2004
    7.2
    High

    CVE-2003-1050

    Last Modified: 7 Nov 2017

    Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

    Source:SNOSoft
    Published:20 Aug 2004
    7.5
    High

    CVE-2003-1041

    Last Modified: 19 Dec 2012

    Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.

    Source:Arman Nayyeri
    Published:20 May 2004
    5
    Medium

    CVE-2003-1032

    Last Modified: 15 Nov 2012

    Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.

    Source:posidron
    Published:26 Jan 2004
    4.3
    Medium

    CVE-2003-1031

    Last Modified: 29 Nov 2012

    Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."

    Source:Ferruh Mavituna
    Published:22 Jan 2004
    7.5
    High

    CVE-2003-1030

    Last Modified: 16 Apr 2026

    Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.

    Source:ash
    Published:15 Jan 2004
    5
    Medium

    CVE-2003-1029

    Last Modified: 17 Dec 2012

    The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.

    Source:Przemyslaw Frasunek
    Published:15 Jan 2004
    9.3
    Critical

    CVE-2003-1026

    Last Modified: 7 Mar 2016

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

    Source:Andreas Sandblad
    Published:8 Jan 2004
    4.3
    Medium

    CVE-2003-1025

    Last Modified: 28 Mar 2019

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."

    Source:Guy Crumpley
    Published:6 Jan 2004
    5
    Medium

    CVE-2003-1017

    Last Modified: 11 Dec 2012

    Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read restricted files via vulnerabilities in web browsers whose exploits rely on predictable names.

    Source:Mindwarper
    Published:17 Dec 2003
    7.2
    High

    CVE-2003-1006

    Last Modified: 16 Dec 2012

    Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.

    Source:Max
    Published:10 Mar 2004
    7.5
    High

    CVE-2003-0990

    Last Modified: 6 Mar 2011

    The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.

    Source:Metasploit
    Published:6 Jan 2004
    7.2
    High

    CVE-2003-0985

    Last Modified: 23 Nov 2016

    The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.

    Source:Paul Starzetz
    Published:5 Jan 2004
    7.5
    High

    CVE-2003-0974

    Last Modified: 16 Dec 2012

    Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using addrule.c.

    Source:Bugtraq Security
    Published:2 Dec 2003
    5
    Medium

    CVE-2003-0967

    Last Modified: 14 Dec 2012

    rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.

    Source:Evgeny Legerov
    Published:20 Nov 2003
    7.5
    High

    CVE-2003-0963

    Last Modified: 7 Mar 2016

    Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.

    Source:Li0n7
    Published:13 Dec 2003
    7.2
    High

    CVE-2003-0961

    Last Modified: 18 Jan 2018

    Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.

    Source:Christophe Devine
    Published:1 Dec 2003
    4.6
    Medium

    CVE-2003-0955

    Last Modified: 22 Nov 2017

    OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.

    Source:Scott Bartram
    Published:21 Nov 2003
    7.2
    High

    CVE-2003-0948

    Last Modified: 18 Jan 2018

    Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.

    Source:Qnix
    Published:18 Nov 2003
    7.2
    High

    CVE-2003-0947

    Last Modified: 27 Oct 2016

    Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.

    Source:axis
    Published:18 Nov 2003
    7.2
    High

    CVE-2003-0910

    Last Modified: 9 Jan 2013

    The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.

    Published:16 Apr 2004
    7.2
    High

    CVE-2003-0908

    Last Modified: 16 Apr 2026

    The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.

    Source:Cesar Cerrudo
    Published:16 Apr 2004
    9.8
    Critical

    CVE-2003-0899

    Last Modified: 15 Nov 2017

    Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

    Source:Joel Soderberg
    Published:30 Oct 2003
    4.6
    Medium

    CVE-2003-0898

    Last Modified: 29 Nov 2012

    IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.

    Source:Juan Manuel Pascual Escribá
    Published:28 Oct 2003
    7.5
    High

    CVE-2003-0896

    Last Modified: 9 Dec 2012

    The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.

    Source:Last Stage of Delirium
    Published:25 Oct 2003
    10
    Critical

    CVE-2003-0886

    Last Modified: 13 Dec 2012

    Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.

    Source:Sebastian Krahmer
    Published:12 Nov 2003
    7.5
    High

    CVE-2003-0870

    Last Modified: 9 Dec 2012

    Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.

    Source:@stake
    Published:21 Oct 2003
    5
    Medium

    CVE-2003-0866

    Last Modified: 9 Dec 2012

    The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.

    Source:Oliver Karow
    Published:17 Oct 2003
    7.5
    High

    CVE-2003-0865

    Last Modified: 5 Dec 2012

    Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.

    Source:V9
    Published:17 Oct 2003